CVE-2025-32754

CRITICAL

Jenkins/ssh-agent Docker <6.11.1 - Privilege Escalation

Title source: llm
STIX 2.1

Description

In jenkins/ssh-agent Docker images 6.11.1 and earlier, SSH host keys are generated on image creation for images based on Debian, causing all containers based on images of the same version use the same SSH host keys, allowing attackers able to insert themselves into the network path between the SSH client (typically the Jenkins controller) and SSH build agent to impersonate the latter.

Scores

CVSS v3 9.1
EPSS 0.0021
EPSS Percentile 43.6%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact total

Details

CWE
CWE-338
Status published
Products (1)
jenkins/ssh-agent < 6.11.2
Published Apr 10, 2025
Tracked Since Feb 18, 2026